2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-11044HIGH7.8An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The ch...
CVE-2016-11043HIGH7.5An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where...
CVE-2016-11042HIGH7.5An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The S...
CVE-2016-11041MEDIUM4.6An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending ...
CVE-2016-11024CRITICAL9.8odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
CVE-2016-11023CRITICAL9.8odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
CVE-2016-11022HIGH7.2NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code wi...
CVE-2016-1000111MEDIUM5.3Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not pro...
CVE-2016-1487HIGH8.8Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execut...
CVE-2016-6918CRITICAL9.8Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading file...
CVE-2016-1159MEDIUM6.5In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain...
CVE-2016-11021HIGH7.2setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in th...
CVE-2016-11020CRITICAL9.8Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote...
CVE-2016-4606CRITICAL9.8Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrar...
CVE-2016-3182MEDIUM5.5The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of ser...
CVE-2016-3181Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3182. Reason: This candidate is a duplicate of C...
CVE-2016-1000109MEDIUM5.3HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applicat...
CVE-2016-1000005CRITICAL9.8mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if ot...
CVE-2016-1000004CRITICAL9.8Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_d...
CVE-2016-5710MEDIUM4.6NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspeci...
CVE-2016-1544LOW3.3nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
CVE-2016-9928HIGH7.4MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or...
CVE-2016-7524MEDIUM6.5coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted fil...
CVE-2016-7523MEDIUM6.5coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted fil...
CVE-2016-4676HIGH7.5A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which c...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now